EARS: Enabling Private Feedback Updates in Anonymous Reputation Systems

EARS: Enabling Private Feedback Updates in Anonymous Reputation Systems
复制标题

DOI:
10.1109/cns48642.2020.9162328
复制
发表时间:
2020-06
期刊:
2020 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Vishnu Teja Kilari;Ruozhou Yu;S. Misra;G. Xue
Vishnu Teja Kilari;Ruozhou Yu;S. Misra;G. Xue
中科院分区:
其他
文献类型:
--
作者:
Vishnu Teja Kilari;Ruozhou Yu;S. Misra;G. Xue

文献摘要

相似文献

信誉系统旨在弥补信息质量的不足,评估信息源的可信度,已成为许多在线系统不可或缺的组成部分。典型的声誉系统的工作原理是跟踪源自某一来源的所有信息,以及对该信息的反馈及其对该来源的归属。对信息和反馈的跟踪虽然至关重要,但可能会侵犯提供信息和/或反馈的用户的隐私,这既可能对用户的在线福祉造成损害,也可能阻碍他们参与。匿名信誉系统旨在通过确保用户的匿名性来保护用户隐私。然而,当前的匿名信誉系统受到几个限制,包括但不限于a)缺乏对诸如反馈更新等核心功能的支持,b)缺乏用于实际部署的协议效率,以及c)依赖于完全可信的机构。本文提出了一种匿名信誉系统EARS,它在保证用户匿名性的同时,高效、实用地支持信誉系统的所有核心功能(包括反馈更新),并且不需要完全可信的中心机构。我们给出了EAR针对多种类型的攻击的安全性分析,这些攻击可能会潜在地违反用户匿名性,如反馈重复、恶言相向和选票填充。我们还根据实现情况对系统的效率和可扩展性进行了评估。
Reputation systems, designed to remedy the lack of information quality and assess credibility of information sources, have become an indispensable component of many online systems. A typical reputation system works by tracking all information originating from a source, and the feedback to the information with its attribution to the source. The tracking of information and the feedback, though essential, could violate the privacy of users who provide the information and/or the feedback, which could both cause harm to the users’ online well-being, and discourage them from participation. Anonymous reputation systems have been designed to protect user privacy by ensuring anonymity of the users. Yet, current anonymous reputation systems suffer from several limitations, including but not limited to a)lack of support for core functionalities such as feedback update, b) lack of protocol efficiency for practical deployment, and c) reliance on a fully trusted authority. This paper proposes EARS, an anonymous reputation system that ensures user anonymity while supporting all core functionalities (including feedback update) of a reputation system both efficiently and practically, and without the need of a fully trusted central authority. We present security analysis of EARS against multiple types of attacks that could potentially violate user anonymity, such as feedback duplication, bad mouthing, and ballot stuffing. We also present evaluation of the efficiency and scalability of our system based on implementations.